
PeopleSoft version 8 users, read on...
Published: 11 March 2003 10:39 GMT
A serious security flaw in business management software from PeopleSoft leaves sensitive corporate data vulnerable to hackers, a computer security service firm warned on Monday.
The flaw, known as a remote command execution vulnerability, gives outsiders the ability to install malicious computer code on PeopleSoft customers' web servers, potentially leading to a "complete compromise" of their PeopleSoft business systems, according to Internet Security Systems (ISS), the Atlanta-based computer security company that issued the warning.
"Compromise of PeopleSoft web server installations may disclose critical confidential information and facilitate the compromise of PeopleSoft application and database back-end servers," stated the ISS advisory.
The flaw affects only certain releases of PeopleSoft version 8, which the company began shipping in 2000. Nearly 2,000 companies have installed version 8, according to PeopleSoft spokesman Steve Swasey. He declined, however, to comment on how many of those customers could be affected by the vulnerability.
The flawed software, which is configured to run by default, affects numerous versions of a core component of its applications called PeopleSoft Tools, including versions 8.4, 8.41 and 8.10 through 8.18. Specifically, the problem pertains to a small Java program, known as a "servlet," that resides on PeopleSoft web servers and can be used to upload files without any authentication. The purpose of the servlet, according to PeopleSoft, is to transfer business reports between servers using Internet protocols such as HTTP (hypertext transfer protocol).
PeopleSoft released patches to correct the problem several weeks ago, Swasey said. The patches and details about the vulnerability are available on the company's private website for PeopleSoft customers as well as through ISS. PeopleSoft has yet to hear of any problems related to the security flaw, Swasey added. An ISS spokesman also said the flaw had not yet been exploited, as far as he knew.
PeopleSoft touts version 8 of its applications as a major advancement of its technology because of its use of Internet protocols. PeopleSoft competitors SAP, Siebel Systems and Oracle have also released software designed to run over the web.
Alorie Gilbert writes for News.com
PeopleSoft HR Consultant Job ID GBS-0052927 Job type Full-time Regular Work country United Kingdom Work city Any city in selected countries Job role ...
Peoplesoft CRM functional team leader needed by my client for a large implementation. The successful candidate will have a very good functional ...
A Software Test Engineer works within the Product Release Group (PRG) within Software Development, and is responsible for fulfilling varying ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...